A study commissioned by the former Department for Digital, Culture, Media & Sport (DCMS) and led by the University of Greenwich has highlighted significant gaps in the cybersecurity evidence base for open-source artificial intelligence (AI).
The research, published today, 7 September 2026, reviewed academic and 'grey' literature on open-source software and open-source AI published between 2020 and 2026. It screened 14,561 academic records, including 43 for inclusion, and 172 grey literature records from various national and international bodies.
The study specifically noted a lack of evidence regarding the upstream governance of open-source AI. The report also sets out recommendations to address these identified gaps. This independent research supports the government's broader efforts to understand the cybersecurity implications of emerging technologies and enhance the UK's cyber resilience.